This document tracks approved deviations from security policies for Hex registry infrastructure.
| ID | Exception | Justification | Approved By | Expiry | Review Date |
|---|
| - | - | - | - | - | - |
- Document the specific policy deviation required
- Provide justification explaining why the exception is necessary
- Describe compensating controls or mitigations in place
- Propose an expiry date or review cadence
| Criterion | Description |
|---|
| Business justification | Clear need for the exception |
| Risk assessment | Understanding of security impact |
| Compensating controls | Mitigations to reduce risk |
| Time-bound | Defined expiry or review date |
- Exceptions are reviewed on their specified review date
- Expired exceptions must be renewed or the deviation corrected
- All active exceptions are reviewed during security audits
| ID | Exception | Expiry | Resolution |
|---|
| - | - | - | - |